NIST Cybersecurity Framework 2.0
Six functions, twenty-two categories and 106 subcategories, each stating an outcome rather than a mechanism. Its subcategory identifiers have become the shared index agencies and vendors describe security outcomes in.
What This Framework Contributes.
The strongest crosswalk on this page and still a partial one: the catalog cites just over half the subcategory set, and the half it does not cite is listed by identifier rather than left as a gap the reader has to find.
- For any cited subcategory, the controls that claim it — each linked to a full reference entry with an evidence artifact and an assessment procedure, which is more than the subcategory itself supplies.
- Govern and Identify content at real depth. Command, intent, phase declaration and the terrain overlay are where this framework does its work, and the citation distribution shows it.
- A route from an outcome an agency is already reporting against to a defensive move that produces it, without a translation exercise.
What it does not do for CSF 2.0.
Read this before the crosswalk, not after it. A reader who takes the mappings below as coverage of CSF 2.0 will be wrong in a way that is expensive to discover later.
- Coverage of the Respond function.One subcategory of thirteen is cited. Response content in this framework lives in the campaign phases and the pre-authorized fires, neither of which is a control, so there is nothing honest to cite. An agency short on Respond should not take it from here.
- Tiers and Profiles.The framework has its own capability scale and its own campaign phasing. A second maturity vocabulary on top would give an agency two answers to the same question and no way to reconcile them.
- Any claim that a cited subcategory is satisfied.A citation says a control bears on an outcome. Whether the outcome is achieved is an assessment result, and it is the agency’s, produced against its own estate.
- Implementation Examples and Informative References.CSF 2.0 ships those separately and updates them on their own cadence. Reproducing them here would create a copy that goes stale silently.
Function by Function, Against the Published Set.
93 of the 106 subcategories in CSF 2.0 are claimed by at least one control. The distribution is lopsided and is published lopsided: Govern is cited through 22 of its 31 subcategories, and no claim of Govern coverage is made on the strength of it.
| Function | Subcategories claimed | Controls claiming them | What the function asks for |
|---|---|---|---|
| GovernGV | 22 of 31 — 71% | 30 of 78 | The organization’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored. |
| IdentifyID | 19 of 21 — 90% | 37 of 78 | The organization’s current cybersecurity risks are understood — its assets, its suppliers, and the improvements its own operations reveal. |
| ProtectPR | 20 of 22 — 91% | 27 of 78 | Safeguards to manage the organization’s cybersecurity risks are used — access, training, data, platforms and infrastructure resilience. |
| DetectDE | 11 of 11 — 100% | 13 of 78 | Possible cybersecurity attacks and compromises are found and analyzed. |
| RespondRS | 13 of 13 — 100% | 12 of 78 | Actions regarding a detected cybersecurity incident are taken — management, analysis, communication and mitigation. |
| RecoverRC | 8 of 8 — 100% | 9 of 78 | Assets and operations affected by a cybersecurity incident are restored, and the restoration is communicated. |
Govern
GV
- Subcategories claimed
- 22 of 31 — 71%
- Controls claiming them
- 30 of 78
- What the function asks for
- The organization’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored.
Identify
ID
- Subcategories claimed
- 19 of 21 — 90%
- Controls claiming them
- 37 of 78
- What the function asks for
- The organization’s current cybersecurity risks are understood — its assets, its suppliers, and the improvements its own operations reveal.
Protect
PR
- Subcategories claimed
- 20 of 22 — 91%
- Controls claiming them
- 27 of 78
- What the function asks for
- Safeguards to manage the organization’s cybersecurity risks are used — access, training, data, platforms and infrastructure resilience.
Detect
DE
- Subcategories claimed
- 11 of 11 — 100%
- Controls claiming them
- 13 of 78
- What the function asks for
- Possible cybersecurity attacks and compromises are found and analyzed.
Respond
RS
- Subcategories claimed
- 13 of 13 — 100%
- Controls claiming them
- 12 of 78
- What the function asks for
- Actions regarding a detected cybersecurity incident are taken — management, analysis, communication and mitigation.
Recover
RC
- Subcategories claimed
- 8 of 8 — 100%
- Controls claiming them
- 9 of 78
- What the function asks for
- Assets and operations affected by a cybersecurity incident are restored, and the restoration is communicated.
Every figure above is counted off the catalog’s own csf arrays against the subcategory register, not off a restatement of them. 78 of the framework’s controls carry at least one citation; 13 subcategories carry none.
Every Subcategory, Claimed or Not.
The uncited rows are the point. A crosswalk that lists only what it covers cannot be checked, because the identifiers it misses appear nowhere in it. Each subcategory below is either linked to the controls that claim it or marked as claimed by nothing.
Govern
GV · 22 of 31 subcategories · 30 controlsThe organization’s cybersecurity risk management strategy, expectations and policy are established, communicated and monitored.
Organizational Context
GV.OC · 4 of 5 claimed- GV.OC-01The organizational mission is understood and informs cybersecurity risk management.
- GV.OC-02Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and considered.Claimed by nothing in this catalog.
- GV.OC-03Legal, regulatory and contractual requirements regarding cybersecurity — including privacy and civil liberties obligations — are understood and managed.
- GV.OC-04Critical objectives, capabilities and services that external stakeholders depend on or expect from the organization are understood and communicated.
- GV.OC-05Outcomes, capabilities and services that the organization depends on are understood and communicated.
Risk Management Strategy
GV.RM · 4 of 7 claimed- GV.RM-01Risk management objectives are established and agreed to by organizational stakeholders.
- GV.RM-02Risk appetite and risk tolerance statements are established, communicated and maintained.
- GV.RM-03Cybersecurity risk management activities and outcomes are included in enterprise risk management processes.
- GV.RM-04Strategic direction that describes appropriate risk response options is established and communicated.Claimed by nothing in this catalog.
- GV.RM-05Lines of communication across the organization are established for cybersecurity risks, including risks from suppliers and other third parties.Claimed by nothing in this catalog.
- GV.RM-06A standardized method for calculating, documenting, categorizing and prioritizing cybersecurity risks is established and communicated.
- GV.RM-07Strategic opportunities — positive risks — are characterized and included in organizational cybersecurity risk discussions.Claimed by nothing in this catalog.
Roles, Responsibilities and Authorities
GV.RR · 3 of 4 claimed- GV.RR-01Organizational leadership is responsible and accountable for cybersecurity risk and fosters a culture that is risk-aware, ethical and continually improving.
- GV.RR-02Roles, responsibilities and authorities related to cybersecurity risk management are established, communicated, understood and enforced.
- GV.RR-03Adequate resources are allocated commensurate with the cybersecurity risk strategy, roles, responsibilities and policies.Claimed by nothing in this catalog.
- GV.RR-04Cybersecurity is included in human resources practices.
Policy
GV.PO · 1 of 2 claimed- GV.PO-01Policy for managing cybersecurity risks is established based on organizational context, cybersecurity strategy and priorities, and is communicated and enforced.
- GV.PO-02Policy for managing cybersecurity risks is reviewed, updated, communicated and enforced to reflect changes in requirements, threats, technology and organizational mission.Claimed by nothing in this catalog.
Oversight
GV.OV · 3 of 3 claimed- GV.OV-01Cybersecurity risk management strategy outcomes are reviewed to inform and adjust strategy and direction.
- GV.OV-02The cybersecurity risk management strategy is reviewed and adjusted to ensure coverage of organizational requirements and risks.
- GV.OV-03Organizational cybersecurity risk management performance is evaluated and reviewed for adjustments needed.
Cybersecurity Supply Chain Risk Management
GV.SC · 7 of 10 claimed- GV.SC-01A cybersecurity supply chain risk management program, strategy, objectives, policies and processes are established and agreed to by organizational stakeholders.
- GV.SC-02Cybersecurity roles and responsibilities for suppliers, customers and partners are established, communicated and coordinated internally and externally.Claimed by nothing in this catalog.
- GV.SC-03Cybersecurity supply chain risk management is integrated into cybersecurity and enterprise risk management, risk assessment and improvement processes.Claimed by nothing in this catalog.
- GV.SC-04Suppliers are known and prioritized by criticality.
- GV.SC-05Requirements to address cybersecurity risks in supply chains are established, prioritized and integrated into contracts and other agreements with suppliers and other relevant third parties.Claimed by nothing in this catalog.
- GV.SC-06Planning and due diligence are performed to reduce risks before entering into formal supplier or other third-party relationships.
- GV.SC-07The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to and monitored over the course of the relationship.
- GV.SC-08Relevant suppliers and other third parties are included in incident planning, response and recovery activities.
- GV.SC-09Supply chain security practices are integrated into cybersecurity and enterprise risk management programs, and their performance is monitored throughout the technology product and service life cycle.
- GV.SC-10Cybersecurity supply chain risk management plans include provisions for activities that occur after the conclusion of a partnership or service agreement.
Identify
ID · 19 of 21 subcategories · 37 controlsThe organization’s current cybersecurity risks are understood — its assets, its suppliers, and the improvements its own operations reveal.
Asset Management
ID.AM · 7 of 7 claimed- ID.AM-01Inventories of hardware managed by the organization are maintained.
- ID.AM-02Inventories of software, services and systems managed by the organization are maintained.
- ID.AM-03Representations of the organization’s authorized network communication and internal and external network data flows are maintained.
- ID.AM-04Inventories of services provided by suppliers are maintained.
- ID.AM-05Assets are prioritized based on classification, criticality, resources and impact on the mission.
- ID.AM-07Inventories of data and corresponding metadata for designated data types are maintained.
- ID.AM-08Systems, hardware, software, services and data are managed throughout their life cycles.
Risk Assessment
ID.RA · 8 of 10 claimed- ID.RA-01Vulnerabilities in assets are identified, validated and recorded.
- ID.RA-02Cyber threat intelligence is received from information sharing forums and sources.
- ID.RA-03Internal and external threats to the organization are identified and recorded.
- ID.RA-04Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.
- ID.RA-05Threats, vulnerabilities, likelihoods and impacts are used to understand inherent risk and inform risk response prioritization.
- ID.RA-06Risk responses are chosen, prioritized, planned, tracked and communicated.
- ID.RA-07Changes and exceptions are managed, assessed for risk impact, recorded and tracked.Claimed by nothing in this catalog.
- ID.RA-08Processes for receiving, analyzing and responding to vulnerability disclosures are established.Claimed by nothing in this catalog.
- ID.RA-09The authenticity and integrity of hardware and software are assessed prior to acquisition and use.
- ID.RA-10Critical suppliers are assessed prior to acquisition.
Improvement
ID.IM · 4 of 4 claimed- ID.IM-01Improvements are identified from evaluations.
- ID.IM-02Improvements are identified from security tests and exercises, including those done in coordination with suppliers and relevant third parties.
- ID.IM-03Improvements are identified from execution of operational processes, procedures and activities.
- ID.IM-04Incident response plans and other cybersecurity plans that affect operations are established, communicated, maintained and improved.
Protect
PR · 20 of 22 subcategories · 27 controlsSafeguards to manage the organization’s cybersecurity risks are used — access, training, data, platforms and infrastructure resilience.
Identity Management, Authentication and Access Control
PR.AA · 6 of 6 claimed- PR.AA-01Identities and credentials for authorized users, services and hardware are managed by the organization.
- PR.AA-02Identities are proofed and bound to credentials based on the context of interactions.
- PR.AA-03Users, services and hardware are authenticated.
- PR.AA-04Identity assertions are protected, conveyed and verified.
- PR.AA-05Access permissions, entitlements and authorizations are defined in a policy, managed, enforced and reviewed, and incorporate least privilege and separation of duties.
- PR.AA-06Physical access to assets is managed, monitored and enforced commensurate with risk.
Awareness and Training
PR.AT · 2 of 2 claimed- PR.AT-01Personnel are provided with awareness and training so that they possess the knowledge and skills to perform general tasks with cybersecurity risks in mind.
- PR.AT-02Individuals in specialized roles are provided with awareness and training so that they possess the knowledge and skills to perform relevant tasks with cybersecurity risks in mind.
Data Security
PR.DS · 3 of 4 claimed- PR.DS-01The confidentiality, integrity and availability of data-at-rest are protected.
- PR.DS-02The confidentiality, integrity and availability of data-in-transit are protected.
- PR.DS-10The confidentiality, integrity and availability of data-in-use are protected.Claimed by nothing in this catalog.
- PR.DS-11Backups of data are created, protected, maintained and tested.
Platform Security
PR.PS · 5 of 6 claimed- PR.PS-01Configuration management practices are established and applied.
- PR.PS-02Software is maintained, replaced and removed commensurate with risk.
- PR.PS-03Hardware is maintained, replaced and removed commensurate with risk.
- PR.PS-04Log records are generated and made available for continuous monitoring.
- PR.PS-05Installation and execution of unauthorized software are prevented.
- PR.PS-06Secure software development practices are integrated, and their performance is monitored throughout the software development life cycle.Claimed by nothing in this catalog.
Technology Infrastructure Resilience
PR.IR · 4 of 4 claimed- PR.IR-01Networks and environments are protected from unauthorized logical access and usage.
- PR.IR-02The organization’s technology assets are protected from environmental threats.
- PR.IR-03Mechanisms are implemented to achieve resilience requirements in normal and adverse situations.
- PR.IR-04Adequate resource capacity to ensure availability is maintained.
Detect
DE · 11 of 11 subcategories · 13 controlsPossible cybersecurity attacks and compromises are found and analyzed.
Continuous Monitoring
DE.CM · 5 of 5 claimed- DE.CM-01Networks and network services are monitored to find potentially adverse events.
- DE.CM-02The physical environment is monitored to find potentially adverse events.
- DE.CM-03Personnel activity and technology usage are monitored to find potentially adverse events.
- DE.CM-06External service provider activities and services are monitored to find potentially adverse events.
- DE.CM-09Computing hardware and software, runtime environments and their data are monitored to find potentially adverse events.
Adverse Event Analysis
DE.AE · 6 of 6 claimed- DE.AE-02Potentially adverse events are analyzed to better understand associated activities.
- DE.AE-03Information is correlated from multiple sources.
- DE.AE-04The estimated impact and scope of adverse events are understood.
- DE.AE-06Information on adverse events is provided to authorized staff and tools.
- DE.AE-07Cyber threat intelligence and other contextual information are integrated into the analysis.
- DE.AE-08Incidents are declared when adverse events meet the defined incident criteria.
Respond
RS · 13 of 13 subcategories · 12 controlsActions regarding a detected cybersecurity incident are taken — management, analysis, communication and mitigation.
Incident Management
RS.MA · 5 of 5 claimed- RS.MA-01The incident response plan is executed in coordination with relevant third parties once an incident is declared.
- RS.MA-02Incident reports are triaged and validated.
- RS.MA-03Incidents are categorized and prioritized.
- RS.MA-04Incidents are escalated or elevated as needed.
- RS.MA-05The criteria for initiating incident recovery are applied.
Incident Analysis
RS.AN · 4 of 4 claimed- RS.AN-03Analysis is performed to establish what has taken place during an incident and the root cause of the incident.
- RS.AN-06Actions performed during an investigation are recorded, and the records’ integrity and provenance are preserved.
- RS.AN-07Incident data and metadata are collected, and their integrity and provenance are preserved.
- RS.AN-08An incident’s magnitude is estimated and validated.
Incident Response Reporting and Communication
RS.CO · 2 of 2 claimed- RS.CO-02Internal and external stakeholders are notified of incidents.
- RS.CO-03Information is shared with designated internal and external stakeholders.
Recover
RC · 8 of 8 subcategories · 9 controlsAssets and operations affected by a cybersecurity incident are restored, and the restoration is communicated.
Incident Recovery Plan Execution
RC.RP · 6 of 6 claimed- RC.RP-01The recovery portion of the incident response plan is executed once initiated from the incident response process.
- RC.RP-02Recovery actions are selected, scoped, prioritized and performed.
- RC.RP-03The integrity of backups and other restoration assets is verified before using them for restoration.
- RC.RP-04Critical mission functions and cybersecurity risk management are considered to establish post-incident operational norms.
- RC.RP-05The integrity of restored assets is verified, systems and services are restored, and normal operating status is confirmed.
- RC.RP-06The end of incident recovery is declared based on criteria, and incident-related documentation is completed.
Derived. Every edge is the inverse of a `csf` array in the published catalog; the denominator is the CSF 2.0 subcategory register below. What the framework takes from this source and what it declines to take is set out in sources and provenance; the controls named on this page each carry their full lineage on their own sheet.